216.73.217.11

Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged

· Published 23/07/2026 22:59

Export JSON

Essential information

Published
23/07/2026 22:59
Modified
Source / Author
AlienVault
Confidence
100/100
Report type(s)
threat-report
Labels / Tags
apache hadoop targeting autonomous attack operations cve-2017-7269 cve-2021-3156 cve-2021-4034 cve-2026-31431 cve-2026-43284 cve-2026-43500 cve-2026-43503 government espionage hades hades implant hermes ai agent hiveserver2 exploitation shadowpad suo5 thailand ministry finance vshell yolo mode
Related entities
7 vulnerabilities (cve), 17 indicators, 5 observables, 16 techniques (mitre), 5 malware

Description

Between July 9-13, 2026, three exposed directories on a Hong Kong server revealed an ongoing cyber espionage operation targeting Thailand's Ministry of Finance. The attack leveraged Hermes, an autonomous AI agent operating in unattended YOLO mode, alongside a custom Go-based implant called . Recovered files included exploit code for multiple vulnerabilities, webshells, stolen credentials, and purpose-built scripts targeting MOF Hadoop infrastructure, mail systems, and GlassFish consoles. The AI agent autonomously enumerated ministry networks using LinPEAS, traversed files, and assessed privilege escalation paths. Infrastructure analysis linked multiple Hong Kong and Malaysian servers through TLS certificates and hardcoded C2 addresses. Chinese-language indicators and historical / presence suggest probable Chinese-speaking attribution, though initial access methods remain undetermined.

External references